Millennium Coordinated Vulnerability Disclosure Policy

Millennium, part of the Grenzebach Group, places a high priority on the security of its products, systems, applications, and digital services. Our multi-layered security approach is regularly validated through recognized certifications, including ISO 27001, and is aligned with IEC 62443. Despite careful development and continuous security measures, vulnerabilities cannot be eliminated.

If you discover a potential vulnerability or security issue affecting a website, application, digital service, or product operated by the Grenzebach Group, we encourage you to report it responsibly. Your support helps us reduce risks for our customers, partners, and the Grenzebach Group.

Reporting Security Vulnerabilities

Contact

Please report security vulnerabilities using one of the following contact methods:

Email: secure@grenzebach.com

Phone: +49 906 982 2000

Online (anonymous): Integrity & Compliance Portal

Please provide as much information as possible, including:

  • A description of vulnerability
  • Affected systems, products, or URLs
  • Steps to reproduce the issue
  • Potential impact
  • Screenshots or log files, if available

How We Handle Reports

After receiving a report, we will:

  • Acknowledge receipt of your report as promptly as possible.
  • Review and validate the reported vulnerability.
  • Assess its potential impact.
  • Initiate appropriate mitigation or remediation measures.
  • Contact the reporting individual if additional information is required.

The time required to process a report depends on the complexity, severity, and affected systems.

Responsible Disclosure

We ask security researchers and other individuals reporting vulnerabilities to follow these principles:

  • Report vulnerabilities confidentially and allow us reasonable time to investigate and remediate them.
  • Do not publicly disclose details of a vulnerability until it has been remediated or coordinated disclosure has been agreed upon.
  • Do not access data that does not belong to you.
  • Do not modify, delete, or impair data or systems.
  • Do not perform activities that could affect the availability or integrity of our systems.
  • Do not exploit vulnerabilities for personal gain or to harm others.

Scope

This policy applies to publicly accessible systems, websites, applications, products, and digital services operated by the Grenzebach Group. This explicitly includes product-related software, firmware, embedded systems, and connected components.

Eligible Vulnerabilities

Any vulnerability with a credible attack scenario that could affect the confidentiality, integrity, or availability of the Grenzebach Group's products, services, or information systems is considered within scope.

Examples include:

  • Authentication or authorization issues
  • Cross-site scripting (XSS)
  • Server-side code execution
  • Security vulnerabilities affecting products, software components, interfaces, or communication mechanisms

Out-of-Scope Findings

Some reports are outside the scope of this policy, including:

  • Vulnerabilities that are already known or have previously been reported ("first come, first served")
  • Findings resulting from activities that violate applicable laws or compliance requirements
  • Vulnerabilities affecting sandbox or test environments without demonstrable impact
  • Version disclosure without security impact or generic email spoofing
  • Social engineering attacks
  • Phishing campaigns
  • Denial-of-service (DoS) or distributed denial-of-service (DDoS) testing
  • Physical security assessments
  • Attacks targeting third-party systems that are outside the control of the Grenzebach Group

Safe Harbor Statement

We welcome reports of security vulnerabilities submitted in good faith and in accordance with this policy.

Provided that you comply with the principles described in this policy and do not violate applicable laws, the Grenzebach Group will not initiate legal action solely because of your vulnerability report or related security research.

This statement does not constitute a waiver of any legal rights and does not apply to activities that result in damage, privacy violations, service disruptions, or any other adverse impact.

Notice

This policy is not a bug bounty program. Reports of security vulnerabilities do not create any entitlement to financial compensation.

Thank You

We appreciate the efforts of security researchers, customers, partners, and users who help improve the security of our systems and products by reporting vulnerabilities responsibly.